mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the toBSON method. A misuse of the vm dependency to perform exec commands in a non-safe environment.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Mongo-express | Mongo-express_project | * | 0.54.0 (excluding) |